Assessment
External Vulnerability Scan
A scoped assessment of internet-facing hosts and services, ranked by severity with clear remediation notes for your IT team.
Who it is for
Small and midsize firms that need a clear picture of weaknesses visible from the public internet before attackers find them.
What you receive
A written findings report with severity rankings, evidence samples, and practical remediation steps your staff or MSP can act on.
Included
- Discovery of in-scope public IP ranges and hostnames
- Authenticated or unauthenticated scanning as agreed in the scope letter
- Severity ranking aligned to common vulnerability scoring practices
- Executive summary suitable for leadership and a technical appendix for IT
- One clarification call after report delivery
Outside this engagement
- Intrusion testing that attempts to exploit findings for access
- Remediation work on your systems
- Continuous monitoring subscriptions
- Social engineering or phishing exercises
How we work
- Scope call to confirm assets, blackout windows, and contacts
- Written scope letter and scan schedule
- External scanning within the agreed window
- Manual review of high-severity findings to reduce noise
- Report delivery and follow-up clarification call
Preparation
Provide an accurate list of public IPs and domains, plus a technical contact reachable during the scan window.
Constraints
Scanning is limited to systems you own or are authorised to test. Out-of-scope hosts are excluded.